OpenSSL License
Also known as OpenSSL, OpenSSL License, OpenSSL-SSLeay License.
- Commercial use
- allowed
- Share alike
- not required
- Attribution
- required (keep the copyright and license notices)
Write this as a license text (needs an account) DALICC reads the model above and writes what it permits, requires and prohibits in plain English. Without an account, the Text download above writes the model out from the vocabulary.
Permissions
-
Charge distribution fee from the text Charging a fee for the act of providing a copy of the work to someone else.
-
Commercial use from the text Using the work to generate income, directly or indirectly, for example by selling it or by using it in advertising.
-
Derivative works from the text Distributing an adaptation of the work and making it available to the public.
-
Derive from the text The text says: "Products derived from this software may not be called "OpenSSL" nor may "OpenSSL" appear in their names without prior written permission of the OpenSSL Project." Creating a new work from the work, such as a translation, adaptation or arrangement of it or of a part of it.
Duties
- Attribution from the text Giving credit to the copyright holders or authors of the work, in the form the licensor asks for.
- Notice from the text Notice: keeping the license and copyright notices with every copy.
- Rename from the text Giving a modified or derived work a name that tells it apart from the original.
-
Duties
- Add statement from the text Attaching terms, notices or statements of one's own to the work or to one's modifications when passing it on.
- Advertising acknowledgement from the text Displaying a prescribed acknowledgement, whose wording dalicc:PromotionSpecification carries, in every advertisement that mentions the work or its use.
- Attribution from the text Giving credit to the copyright holders or authors of the work, in the form the licensor asks for.
- Notice from the text Notice: keeping the license and copyright notices with every copy.
-
Modified works from the text Distributing a modified version of the work that does not amount to a new, derivative work.
-
Modify from the text Altering the work, for example by updating it, without creating a new work; an alteration that creates a new work is Derive.
Duties
- Attribution from the text Giving credit to the copyright holders or authors of the work, in the form the licensor asks for.
- Notice from the text Notice: keeping the license and copyright notices with every copy.
- Rename from the text Giving a modified or derived work a name that tells it apart from the original.
-
Present from the text Performing the work in public, including by broadcast or other communication to the public.
Prohibitions
-
Change license from the text Not permitted: Change license. Replacing the license of the work, or of an adaptation, with another license, or changing its terms.
-
Promote from the text Not permitted: Promote. The text says: "The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to endorse or promote products derived from this software without prior written permission." Using the name or trademarks of the licensor or of contributors to endorse or promote a product.
License-wide duties
This license states no duties that apply to the work as a whole.
What applies by default
The statements above are the library's reading of this license: each is marked with the sentence it rests on, or as a library convention where the text is not explicit. The statements below are the ones the DALICC reasoner supplies for acts the license says nothing about, from the default rules of the dependency graph it reasons with. Each one names the legal source it rests on. None of it is in the record.
No default rule of that graph reaches this license: it speaks about every act the rules are about.
Clauses
Warranty disclaimer
THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
Limitation of liability
IN NO EVENT SHALL THE OpenSSL PROJECT OR ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
Additional clauses
3. All advertising materials mentioning features or use of this software must display the following acknowledgment: "This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit. (http://www.openssl.org/)"
Promotion specification
This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit. (http://www.openssl.org/)
Info
- Target asset types
- Software
- Region / jurisdiction
- Worldwide
- Validity
- Perpetual
- Source
- https://spdx.org/licenses/OpenSSL.html
- Legal code
- https://spdx.org/licenses/OpenSSL.html
- This description is published under
- Creative Commons Attribution 4.0 International
- Publisher
- The OpenSSL Project
- Attribution name
- The OpenSSL Project
- SPDX identifier
-
OpenSSLon the SPDX license list - DALICC identifier
OpenSSL
This record is published under CC BY 4.0. Credit it as: DALICC License Library, DALICC - Verein zur Förderung der Rechtssicherheit in der Datenbewirtschaftung, https://dalicc.net, CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). The license it describes belongs to its publisher.
Use this license
Everything below is generated from this record. Replace the example address with the address of your own work.
JSON sidecar
{
"license-uri": "https://dalicc.net/licenselibrary/OpenSSL",
"license-title": "OpenSSL License",
"spdx-id": "OpenSSL",
"attribution": "Copyright (c) [year] [copyright holder]",
"asset": null,
"generated-by": "DALICC"
}
RDF, Turtle
@prefix cc: <http://creativecommons.org/ns#> .
<https://example.org/my-work>
cc:license <https://dalicc.net/licenselibrary/OpenSSL> .
RDF, JSON-LD
{
"@context": {
"cc": "http://creativecommons.org/ns#"
},
"@id": "https://example.org/my-work",
"cc:license": {
"@id": "https://dalicc.net/licenselibrary/OpenSSL"
}
}
HTML attribution
<p>This work is licensed under <a href="https://dalicc.net/licenselibrary/OpenSSL" rel="license">OpenSSL License</a>.</p>
This license asks for attribution, so the credit line is part of it.
Badge
Markdown
[](https://dalicc.net/license-library/OpenSSL)
HTML
<a href="https://dalicc.net/license-library/OpenSSL"><img src="https://dalicc.net/license-library/OpenSSL/badge.svg" alt="License: OpenSSL License"></a>
Review
- Written from the license text by
- Giray Havur
- Written on
- 2026-09-22
- Second review
- not yet done
- Record changed since this review
- yes (version 2, 2026-09-24)
- Findings
- 13 recorded, 11 applied to the record, 0 proposed
Models the licence that governed OpenSSL up to version 3: two agreements in one document, the OpenSSL License and the original SSLeay License, both of which a licensee must satisfy. Both are six- and four-clause BSD texts with advertising acknowledgements. The SSLeay half ends with a sentence that forbids changing the licence terms, which is why this record prohibits dalicc:ChangeLicense.
13 findings
-
info Rubric 1
spdx:licenseIdappliedFile name, record identifier, SPDX identifier and IRI local name are all OpenSSL. The SPDX identifier covers both halves of the document, so one record models both.
-
info Rubric 2
odrl:targetappliedOne odrl:AssetCollection of dct:type dcmitype:Software. Both halves govern source and binary forms of a library.
-
major Rubric 3
odrl:permissionappliedThe grant of the OpenSSL half reads "Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met", and the SSLeay half says "This library is free for commercial and non-commercial use as long as the following conditions are aheared to". The record permits reproduce, distribute, modify, derive, display, present, commercial use, derivative works, modified works and the distribution fee.
-
major Rubric 4
odrl:prohibitionapplieddalicc:ChangeLicense is prohibited. The last sentence of the SSLeay half reads "The licence and distribution terms for any publically available version or derivative of this code cannot be changed. i.e. this code cannot simply be copied and put under another distribution licence [including the GNU Public Licence.]" That is an express bar on relicensing, not a notice condition, so the record departs from family rule 15 here.
-
major Rubric 4
odrl:prohibitionapplieddalicc:promote is prohibited for clause 4 of the OpenSSL half, "The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to endorse or promote products derived from this software without prior written permission".
-
major Rubric 5
odrl:dutyappliedcc:Attribution and cc:Notice hang off odrl:distribute, odrl:modify and odrl:derive for clauses 1 and 2 of both halves and for the SSLeay sentence "any Copyright notices in the code are not to be removed ... Eric Young should be given attribution as the author of the parts of the library used".
-
minor Rubric 5
odrl:dutyapplieddalicc:advertisingAcknowledgement hangs off odrl:distribute for clause 3 of each half, and dalicc:addStatement for clause 6 of the OpenSSL half and clause 4 of the SSLeay half, which put a prescribed acknowledgement on a redistribution of any form rather than on advertising. dalicc:rename hangs off odrl:modify and odrl:derive for clause 5, "Products derived from this software may not be called "OpenSSL"".
-
info Rubric 6
dalicc:PromotionSpecificationapplieddalicc:PromotionSpecification carries the OpenSSL acknowledgement wording, following Apache-1.1. The SSLeay acknowledgement wording is quoted inside its clause in dalicc:additionalClauses, because the property holds one literal and the two wordings are different.
-
minor Rubric 6
dalicc:WarrantyDisclaimerappliedThe document carries two disclaimer paragraphs, one per half. dalicc:WarrantyDisclaimer and dalicc:LiabilityLimitation quote the OpenSSL one, which is the half the licence is named after; the SSLeay disclaimer is the same BSD wording with another party named and is not quoted a second time. The typewriter quotation marks (``AS IS'') and the spellings "aheared" and "rouines" are the text's own.
-
info Rubric 7
cc:jurisdictionappliedThe text names no legal system and sets no term, so cc:jurisdiction is dalicc:worldwide and dalicc:validityType is dalicc:perpetual.
-
info Rubric 8
dalicc:composedOfnoneThe document is a stack of two agreements, which dalicc:composedOf is made for, but the library holds no separate record for the SSLeay licence, so there is nothing to point at. Both halves are modelled in this record instead and every clause of both is quoted.
-
info Rubric 9
recordnoneThe consistency check of app.services.composer against the dependency graph dg_default returned an empty conflict list.
-
major Rubric 10
recordappliedRead against licensedata/licenses/Apache-1.0.ttl, which this addition also creates, the clause structure is the same and the two records differ in one statement: OpenSSL prohibits dalicc:ChangeLicense because its text says the terms cannot be changed. the library conventions (see the review method, docs/LICENSE_REVIEW.md section 9) counted that as a violation of rule 15 until it gained an exception list for the two texts that bar relicensing outright, which this record is on.
Report an issue The review record as JSON The review checks the model against the license text. It is not legal advice.
History
This license model has 2 versions. Version 2 is the one served today; every earlier version keeps its own address, so a conclusion drawn from one of them can still be checked against it.
-
Version 2 current2026-09-24 Giray Havur
The changes since version 1 recorded which sentence of the text each statement rests on and named the license the record itself is published under.
View version 2 JSON-LD Turtle RDF/XML
3 changes
-
changed
permission odrl:derive with duties [cc:Attribution, cc:Notice, dalicc:rename]was
permission odrl:derive with duties [cc:Attribution, cc:Notice, dalicc:rename]Manual edit The statement now quotes the sentence of the licence text it rests on: "Products derived from this software may not be called "OpenSSL" nor may "OpenSSL" appear in their names without prior written permission of the OpenSSL Project."
-
changed
prohibition dalicc:promotewas
prohibition dalicc:promoteManual edit The statement now quotes the sentence of the licence text it rests on: "The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to endorse or promote products derived from this software without prior written permission."
-
added
dct:license <https://creativecommons.org/licenses/by/4.0/>Manual edit Every record is published under CC BY 4.0. cc:license names the record DALICC keeps of that licence; dct:license now names it by the address Creative Commons publishes it at, so that a consumer matching the canonical IRI finds it.
-
-
Version 1
Created from the license text on 2026-09-22 (Permissive variants).
Every change names the reason behind it: a finding of the content review, one of its library-wide decisions, the metadata that review wrote onto every record, or a hand edit. None of it is legal advice.
Nothing on this page is legal advice. What a license means is decided by its text; ask a legal advisor before you rely on it.